ai-gateway
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose is coherent, but its trust model is weak: it asks users to install a non-Vercel third-party CLI and forward a Vercel API key through it. Data flows otherwise appear aligned with the stated purpose, and there is no confirmed malware or hidden execution, but the credential-forwarding and publisher mismatch make the skill high risk.
Confidence: 91%Severity: 72%
Audit Metadata